Junglewise Threat Intelligence

CVE-2026-56786: RTKLIB out-of-bounds write in decode_type1033

CVE-2026-56786 · Severity: critical · CVSS 9.8 · Published 2026-06-25

Technologies: Tomoji Takasu RTKLIB. Vendors: Tomoji Takasu.

Executive brief

RTKLIB is an open-source library used for high-precision Global Navigation Satellite System (GNSS) positioning. A vulnerability in its data processing component allows an attacker to send specially crafted satellite correction data that can crash the software or potentially take control of the system. This could lead to a loss of positioning services or unauthorized access to devices using this library for navigation.

Technical details

An out-of-bounds write vulnerability exists in RTKLIB's RTCM3 decoder, specifically within the `decode_type1033` function (and similarly in `decode_type1007` and `decode_type1008`). The root cause is a failure to clamp five 8-bit length counters (n, m, n1, n2, n3) against the fixed 64-byte destination buffer size (`MAXANT`) in the `rtcm_t` object. While the code verifies that the input frame is large enough to contain the data, it does not check if the data exceeds the destination field bounds. An attacker controlling an NTRIP or serial RTCM3 stream can provide a length of up to 255, resulting in a 191-byte overflow per field. This corrupts adjacent members of the `rtcm_t` structure, enabling arbitrary code execution or denial of service. The vulnerability is reachable via unauthenticated network or serial streams.

Affected products

  • tomojitakasu RTKLIB through 2.4.3

Timeline

  • 2026-06-09: disclosed: Vulnerability identified by FuzzingLabs and reported to maintainer.
  • 2026-06-25: advisory: CVE-2026-56786 published.

References

Related threats